ComputeDriver feature matrix
Compare the bundled Compute Drivers before choosing where to run Agents. The first table summarizes current Agent deployment paths. The detailed capability matrix is a reviewed source snapshot: it describes implementation components, not proof that a complete deployment or model request works. Its baseline and review date are shown above the generated table.
The local docs preview adds search, filters, and expandable source/test evidence to this page. On GitHub, status links in the table open pinned implementation sources. Full cell explanations and evidence are in the canonical matrix data.
Which Drivers can deploy an Agent?
| Driver | Current Agent deployment |
|---|---|
| Kubernetes | Embedded OpenClaw supports an OCC Secret-backed API key. Dedicated Codex supports an OCC Secret-backed API key or a managed ChatGPT service-account credential. |
| SSH | Supports embedded OpenClaw with harnessAuth.method: runtime; an operator must supply the model credential on the Linux host. No OCC-managed model credentials or dedicated Codex. |
| Docker/Podman | Runs the local control plane, but rejects all current model-authentication bindings. A newly admitted Agent cannot be deployed through this Driver. |
An optional OpenShell Sandbox Driver can be selected with Kubernetes, but stock OpenShell lacks required credential and workload-identity projection. It is not a supported Agent deployment path. The bundled Compute Drivers expose the current gateway authentication contracts:
| Driver | Gateway authentication |
|---|---|
| Kubernetes | Trusted proxy only, with optional loopback password access. |
| Docker/Podman | Managed password by default; explicit trusted proxy remains supported by the underlying container code. Current Agent admission limits still apply. |
| SSH | Managed password by default; explicit trusted proxy remains supported. |
Current Kubernetes storage uses a private Gateway RWO claim and a separate Harness-only RWO workspace. Replacements stop predecessors before starting the candidate. See the current storage contract.
The detailed matrix retains its older source baseline. Its shared-workspace/RWX and trusted-proxy rows are historical observations, not current storage or credential requirements. Use the current contracts above for those behaviors. For setup, see Drivers quickstart. The Compute Driver contract owns requirements; the platform architecture distinguishes implementation from remaining design work.
Read the matrix
- Supported: the inspected implementation provides the scoped behavior.
- Partial: the behavior has a material restriction explained in the cell.
- Unsupported: the implementation rejects or does not provide the behavior.
- Unknown: the available evidence does not establish the behavior.
A checkmark describes an individual implementation component. For example, Docker's embedded and dedicated topology code earns checkmarks in the pinned table, even though current Agent authentication prevents a new deployment. A required-contract row records an obligation; optional-capability rows record choices. Production also requires activation stages. Tests linked in the interactive view were not executed in this source review. No cell certifies a live model response or production readiness. Contributors can use the testing guide for runtime verification.
Bundled implementations
- Docker runs the Compose control plane on Docker or Podman for development.
- Kubernetes supports Kubernetes workload orchestration and production configuration.
- SSH runs embedded OpenClaw on operator-provisioned Linux/systemd hosts.
LocalTest is not a bundled selectable implementation in this snapshot. External ComputeDriver packages remain an extension point, not an additional implementation with inferred support. Selection and preflight rules belong to Driver selection.
Capabilities
ComputeDriver feature matrix
Unknown means the available evidence does not establish support for that driver cell. Test links identify repository coverage only; they are not live-runtime proof.
32 rows
| Capability | Requirement | Docker / Podman | Kubernetes | SSH |
|---|---|---|---|---|
| SelectionProduction startup selection | implementation boundaryRequirement sourceapps/controller/src/composition/installation-config.ts:647-690 | UnsupportedDevelopment-only Docker implementation; lacks production activation stages. Sourcedocs/reference/drivers/docker-compute.md:9-12, apps/controller/src/drivers/compute/docker/index.ts:418-424 Live proof: unknown/not run | SupportedBundled production Kubernetes selection; requires explicit cluster configuration. Tests (not run)Live proof: unknown/not run | SupportedBundled compute-ssh selects occ/ssh in production; SSH is now on main. Tests (not run)Live proof: unknown/not run |
| LifecyclePrepare Namespace infrastructure | required contractRequirement source | SupportedCreates or verifies one owned bridge network per Namespace. Live proof: unknown/not run | SupportedCreates or verifies tenant namespace, quotas, defaults and baseline network policy. Live proof: unknown/not run | SupportedCreates or verifies marker on host selected by exact Namespace name. Sourceapps/controller/src/drivers/compute/ssh/index.ts:316-327, apps/controller/src/drivers/compute/ssh/remote-helper.cjs:713-733 Live proof: unknown/not run |
| LifecycleDelete owned Namespace resources | required contractRequirement source | SupportedVerifies network ownership, removes owned containers and exact network. Live proof: unknown/not run | SupportedVerifies ownership; retains externally managed namespace while removing owned infrastructure. Live proof: unknown/not run | SupportedStops owned units, removes owned Namespace tree and runtime identities. Sourceapps/controller/src/drivers/compute/ssh/index.ts:329-342, apps/controller/src/drivers/compute/ssh/remote-helper.cjs:668-710 Tests (not run)Live proof: unknown/not run |
| LifecyclePrepare immutable AgentRevision | required contractRequirement source | SupportedChecks pinned driver, topology and configuration ownership before container preparation. Live proof: unknown/not run | SupportedPrepares exact topology and owned resources with immutable configuration snapshots. Sourceapps/controller/src/drivers/compute/kubernetes/index.ts:1184-1245, apps/controller/src/drivers/compute/kubernetes/index.ts:1383-1408 Live proof: unknown/not run | SupportedWrites immutable snapshot without changing current serving revision. Sourceapps/controller/src/drivers/compute/ssh/index.ts:345-377, apps/controller/src/drivers/compute/ssh/remote-helper.cjs:562-625 Tests (not run)Live proof: unknown/not run |
| LifecycleExplicit activation and deactivation stages | required in production Optional methods in the shared interface; production startup rejects a selected ComputeDriver without both activation stages. | UnsupportedNo activation or deactivation methods; development prepare directly replaces gateway. Sourceapps/controller/src/drivers/compute/docker/index.ts:369-393, apps/controller/src/drivers/compute/docker/index.ts:483-494 Live proof: unknown/not run | SupportedProduction stages verify exact workload readiness and update revision-aware Service routing. Sourceapps/controller/src/drivers/compute/kubernetes/index.ts:1540-1558, apps/controller/src/drivers/compute/kubernetes/index.ts:1630-1661, apps/controller/src/drivers/compute/kubernetes/index.ts:1723-1759 Live proof: unknown/not run | PartialActivation switches snapshot and restarts gateway; deactivation only verifies revision because dedicated topology is unsupported. Sourceapps/controller/src/drivers/compute/ssh/index.ts:380-406, apps/controller/src/drivers/compute/ssh/index.ts:421-424, apps/controller/src/drivers/compute/ssh/remote-helper.cjs:626-665 Tests (not run)Live proof: unknown/not run |
| LifecycleStop exact revision without retiring it | required contractRequirement source | SupportedRemoves exact revision containers; leaves persisted revision outside Driver untouched; runtime tmpfs is lost. Tests (not run)Live proof: unknown/not run | SupportedStops routing and execution while retaining persistent claims. Sourceapps/controller/src/drivers/compute/kubernetes/index.ts:1763-1796, apps/controller/src/drivers/compute/kubernetes/index.ts:1831-1891 Tests (not run)Live proof: unknown/not run | SupportedStops unit and removes current/served pointers while retaining snapshots and Agent state. Sourceapps/controller/src/drivers/compute/ssh/index.ts:426-430, apps/controller/src/drivers/compute/ssh/remote-helper.cjs:759-771 Tests (not run)Live proof: unknown/not run |
| LifecycleRetire predecessor without removing replacement | required contractRequirement source | SupportedRemoves exact revision Agent container; removes gateway only if its revision ID still matches. Live proof: unknown/not run | SupportedRetires owned workload and preserves replacement gateway and claims. Sourceapps/controller/src/drivers/compute/kubernetes/index.ts:1798-1829, apps/controller/src/drivers/compute/kubernetes/index.ts:1959-1987 Tests (not run)Live proof: unknown/not run | SupportedRetires only exact snapshot; stops unit only when retired revision is current. Sourceapps/controller/src/drivers/compute/ssh/index.ts:433-437, apps/controller/src/drivers/compute/ssh/remote-helper.cjs:759-773 Tests (not run)Live proof: unknown/not run |
| TopologyEmbedded OpenClaw Harness | implementation boundaryRequirement source | SupportedOne combined gateway/Harness container. Live proof: unknown/not run | SupportedCombined gateway/Harness Deployment, with Agent service identity. Live proof: unknown/not run | SupportedSupported topology: systemd-managed OpenClaw gateway. Sourceapps/controller/src/drivers/compute/ssh/index.ts:351-355, apps/controller/src/drivers/compute/ssh/remote-helper.cjs:503-532 Live proof: unknown/not run |
| TopologyDedicated Codex Harness | implementation boundaryRequirement source | PartialSeparate gateway and exact-revision Codex container; transport retry limitation is listed separately. Live proof: unknown/not run | SupportedSeparate exact-revision Codex Deployment or selected Sandbox workload. Live proof: unknown/not run | UnsupportedExplicitly rejects non-embedded OpenClaw; dedicated Codex deferred. Tests (not run)Live proof: unknown/not run |
| LifecyclePreserve serving runtime until activation | implementation boundaryRequirement source | UnsupportedPrepare removes prior gateway before creating replacement; no separate activation. Live proof: unknown/not run | SupportedPreparation preserves predecessor; activation performs gateway replacement and routing cutover. Sourceapps/controller/src/drivers/compute/kubernetes/index.ts:1383-1408, apps/controller/src/drivers/compute/kubernetes/index.ts:1540-1605 Tests (not run)Live proof: unknown/not run | SupportedPrepare leaves current pointer and gateway untouched; activation switches and restarts. Tests (not run)Live proof: unknown/not run |
| LifecycleZero-downtime gateway replacement | implementation boundary | UnsupportedReplacement removes previous gateway first. Live proof: unknown/not run | UnsupportedGateway uses one replica and Recreate; transient downtime and node-fencing limits remain. Sourceapps/controller/src/drivers/compute/kubernetes/index.ts:4184-4185, docs/reference/drivers/kubernetes-compute.md:156-161 Live proof: unknown/not run | UnsupportedActivation restarts existing systemd unit, interrupting service. Sourcedocs/reference/drivers/ssh-compute.md:162-169, apps/controller/src/drivers/compute/ssh/remote-helper.cjs:626-665 Live proof: unknown/not run |
| PlacementAdopt an existing tenant namespace | optional capabilityRequirement sourceapps/controller/src/drivers/compute/kubernetes/index.ts:1041-1088 | UnsupportedNo Kubernetes existingNamespace adoption; own Docker network only. Live proof: unknown/not run | SupportedExplicit adoption verifies active namespace, ownership uniqueness and existing network policy before claiming. Tests (not run)tests/conformance/kubernetes-compute.test.mjs:204-227, tests/integration/kubernetes-compute-real.test.mjs:1110-1123 Live proof: unknown/not run | UnsupportedRejects existingNamespace input. Tests (not run)Live proof: unknown/not run |
| CompositionDelegate dedicated Harness to SandboxDriver | optional capabilityRequirement source | UnsupportedNo Sandbox composition in Docker development implementation. Sourcedocs/reference/drivers/compute.md:46-49, apps/controller/src/drivers/compute/docker/index.ts:379-391 Live proof: unknown/not run | SupportedDelegates provisioning to selected SandboxDriver with exact identity and workload requirements; waits for exact ready Pod. Tests (not run)tests/conformance/kubernetes-compute.test.mjs:2005-2047, tests/conformance/kubernetes-compute.test.mjs:2211-2235 Live proof: unknown/not run | UnsupportedExplicitly rejects SandboxDriver selection. Tests (not run)Live proof: unknown/not run |
| CompositionSelected-driver lifecycle hooks | optional capabilityRequirement source | SupportedDispatches Namespace, start, stop and delete hooks; compensates failed preparation. Sourceapps/controller/src/drivers/compute/docker/index.ts:250-255, apps/controller/src/drivers/compute/docker/index.ts:297-297, apps/controller/src/drivers/compute/docker/index.ts:313-313, apps/controller/src/drivers/compute/docker/index.ts:366-414, apps/controller/src/drivers/compute/docker/index.ts:434-434 Live proof: unknown/not run | SupportedDispatches hooks around owned Namespace/workload lifecycle. Sourceapps/controller/src/drivers/compute/kubernetes/index.ts:1117-1120, apps/controller/src/drivers/compute/kubernetes/index.ts:1477-1478, apps/controller/src/drivers/compute/kubernetes/index.ts:1831-1865 Tests (not run)Live proof: unknown/not run | SupportedDispatches hooks around Namespace operations, activation and stop with failure compensation. Sourceapps/controller/src/drivers/compute/ssh/index.ts:316-335, apps/controller/src/drivers/compute/ssh/index.ts:403-417, apps/controller/src/drivers/compute/ssh/index.ts:426-437 Tests (not run)Live proof: unknown/not run |
| CompositionInstall admitted native plugins | optional capabilityRequirement source | SupportedPasses admitted plugin runtime to owning gateway or dedicated Agent. Sourceapps/controller/src/drivers/compute/docker/index.ts:359-390, apps/controller/src/drivers/compute/docker/index.ts:688-727 Tests (not run)Live proof: unknown/not run | SupportedProjects plugin runtime and gates native readiness; configures required egress. Sourceapps/controller/src/drivers/compute/kubernetes/index.ts:1479-1494, apps/controller/src/drivers/compute/kubernetes/index.ts:3950-3985 Tests (not run)Live proof: unknown/not run | UnsupportedRejects revisions whose admitted plugin map is nonempty; an empty map does not trigger this check. Sourceapps/controller/src/drivers/compute/ssh/index.ts:130-132, apps/controller/src/drivers/compute/ssh/index.ts:367-369 Live proof: unknown/not run |
| IsolationTenant network isolation | implementation boundary | PartialSeparate Namespace bridges; no per-workload default-deny ingress/egress policy. Sourceapps/controller/src/drivers/compute/docker/index.ts:270-298, apps/controller/src/drivers/compute/docker/index.ts:611-634 Live proof: unknown/not run | SupportedDefault-deny ingress/egress plus explicit DNS and approved gateway ingress rules; requires enforcing cluster. Sourceapps/controller/src/drivers/compute/kubernetes/index.ts:3154-3178, docs/reference/drivers/kubernetes-compute.md:18-20 Live proof: unknown/not run | UnsupportedSeparate Unix accounts, but shared host networking; operator owns network isolation. Live proof: unknown/not run |
| IsolationExplicit CPU/memory limits and tenant quotas | implementation boundaryRequirement source | UnsupportedContainer create sets bounded tmpfs, but no CPU/memory resource limits or tenant quota. Live proof: unknown/not run | SupportedNamespace ResourceQuota and LimitRange; explicit role-specific Pod resources. Sourceapps/controller/src/drivers/compute/kubernetes/index.ts:1090-1113, apps/controller/src/drivers/compute/kubernetes/index.ts:4235-4238 Tests (not run)Live proof: unknown/not run | Unsupportedsystemd unit has no CPU/memory quota directives. Live proof: unknown/not run |
| IsolationNon-root workload execution | implementation boundary | SupportedContainers run as UID/GID 1000. Live proof: unknown/not run | SupportedPod security context requires non-root UID/GID 1000. Live proof: unknown/not run | SupportedPer-Agent non-login Unix account; SSH control connection itself requires root. Sourceapps/controller/src/drivers/compute/ssh/remote-helper.cjs:313-366, apps/controller/src/drivers/compute/ssh/remote-helper.cjs:503-516, apps/controller/src/drivers/compute/ssh/index.ts:237-240 Tests (not run)Live proof: unknown/not run |
| IsolationWorkload filesystem and privilege restrictions | implementation boundaryRequirement source | SupportedRead-only rootfs, dropped capabilities, no-new-privileges and bounded writable tmpfs. Live proof: unknown/not run | SupportedRestricted Pod context, read-only rootfs, no escalation and dropped capabilities; bounded emptyDir. Sourceapps/controller/src/drivers/compute/kubernetes/index.ts:4031-4038, apps/controller/src/drivers/compute/kubernetes/index.ts:4239-4243 Live proof: unknown/not run | PartialPrivate Unix account, NoNewPrivileges and PrivateTmp; no container-equivalent read-only rootfs. Live proof: unknown/not run |
| IdentityProject service-principal workload token | implementation boundaryRequirement source | UnsupportedService-principal labels, but no projected workload token. Live proof: unknown/not run | SupportedProjects bounded audience-scoped ServiceAccount token read-only; disables ambient automount. Sourceapps/controller/src/drivers/compute/kubernetes/index.ts:3988-4007, apps/controller/src/drivers/compute/kubernetes/index.ts:4199-4200 Tests (not run)Live proof: unknown/not run | UnsupportedBinds ServicePrincipal in ownership markers; no workload token projection. Sourceapps/controller/src/drivers/compute/ssh/index.ts:297-313, apps/controller/src/drivers/compute/ssh/remote-helper.cjs:167-173 Live proof: unknown/not run |
| ConnectivityResolve private WSS gateway endpoint | optional capabilityRequirement source | UnsupportedOptional resolver absent. Live proof: unknown/not run | SupportedReturns deterministic WSS address only when gateway routing is configured. Sourceapps/controller/src/drivers/compute/kubernetes/index.ts:861-865, apps/controller/src/drivers/compute/kubernetes/index.ts:3224-3236 Tests (not run)Live proof: unknown/not run | UnsupportedOptional resolver absent; workspace-file API endpoint resolution unsupported. Live proof: unknown/not run |
| StoragePersist Agent state across runtime replacement | implementation boundary | UnsupportedWritable state is ephemeral tmpfs; no persistent workspace contract. Sourceapps/controller/src/drivers/compute/docker/index.ts:616-624, docs/reference/drivers/docker-compute.md:112-116 Live proof: unknown/not run | SupportedPrivate gateway RWO disk; embedded default workspace persists; dedicated RWX workspace is separate. Sourcedocs/reference/drivers/kubernetes-compute/storage-and-credentials.md:33-60, apps/controller/src/drivers/compute/kubernetes/index.ts:4041-4062 Tests (not run)Live proof: unknown/not run | SupportedPrivate home/state directories persist across stop and revision retirement. Sourceapps/controller/src/drivers/compute/ssh/remote-helper.cjs:562-625, apps/controller/src/drivers/compute/ssh/remote-helper.cjs:759-771 Tests (not run)Live proof: unknown/not run |
| StorageShare dedicated gateway/Harness workspace | implementation boundary | UnsupportedSeparate ephemeral runtime homes; no shared volume mounts. Live proof: unknown/not run | SupportedShared Agent-owned 40Gi RWX claim with directional mount permissions. Sourcedocs/reference/drivers/kubernetes-compute/storage-and-credentials.md:56-60, apps/controller/src/drivers/compute/kubernetes/index.ts:4041-4047 Live proof: unknown/not run | UnsupportedDedicated topology unsupported. Live proof: unknown/not run |
| CredentialsProvision initial Agent runtime credentials | optional capabilityRequirement source | UnsupportedNo provisioning API; model credential supplied to development worker environment. Sourceapps/controller/src/drivers/compute/docker/index.ts:368-384, docs/reference/drivers/compute.md:151-160 Live proof: unknown/not run | SupportedCreates missing owned Secret groups; rejects conflicts and preserves matching existing values. Live proof: unknown/not run | UnsupportedOperator-owned Agent env file is the credential path; no runtime-credential API. Live proof: unknown/not run |
| CredentialsDeliver model credential only to executing Harness | implementation boundary | SupportedProvider key reaches embedded gateway or dedicated Agent; dedicated gateway gets only transport. Live proof: unknown/not run | SupportedAgent harnessAuth selects an OCC Secret API key or account-owned token; only the model-executing workload receives it. Sourceapps/controller/src/drivers/compute/kubernetes/index.ts:4076-4091, apps/controller/src/drivers/compute/kubernetes/index.ts:4121-4138 Tests (not run)tests/conformance/kubernetes-compute.test.mjs:782-837, tests/conformance/kubernetes-compute.test.mjs:948-977 Live proof: unknown/not run | PartialOperator env supplies embedded workload credentials; no Driver-managed model credential path. Sourcedocs/reference/drivers/ssh-compute.md:203-207, apps/controller/src/drivers/compute/ssh/remote-helper.cjs:521-521 Live proof: unknown/not run |
| CredentialsProject OCC Secret bindings | optional capability | UnsupportedprepareRevision does not consume ComputeRevisionContext or project OCC Secret bindings. Sourceapps/controller/src/drivers/compute/docker/index.ts:324-324, apps/controller/src/drivers/compute/docker/index.ts:368-390 Live proof: unknown/not run | PartialCustom bindings are projected into gateway only; dedicated Codex receives an empty projection list. Built-in model/transport credentials use separate supported paths. Sourceapps/controller/src/drivers/compute/kubernetes/index.ts:1389-1405, apps/controller/src/drivers/compute/kubernetes/index.ts:1479-1494, apps/controller/src/drivers/compute/kubernetes/index.ts:4018-4027 Live proof: unknown/not run | UnsupportedExplicitly rejects OCC Secret bindings; operator env file is separate. Tests (not run)Live proof: unknown/not run |
| CredentialsBackend-issued dedicated Codex access token | optional capability | UnsupportedOnly provider API-key environment supported in this implementation. Sourceapps/controller/src/drivers/compute/docker/index.ts:368-390, apps/controller/src/drivers/compute/docker/index.ts:677-686 Live proof: unknown/not run | SupportedAccount-owned access-token Secret and workspace ID project only to dedicated Codex. Tests (not run)Live proof: unknown/not run | UnsupportedDedicated Codex unsupported. Live proof: unknown/not run |
| CredentialsPersist dedicated transport authentication across retries | implementation boundaryRequirement source | PartialSource-inferred retry gap, unreproduced: a fresh token is generated each prepare, while a healthy existing Agent is reused; rebuilding only gateway can supply a different token. Sourceapps/controller/src/drivers/compute/docker/index.ts:379-390, apps/controller/src/drivers/compute/docker/index.ts:483-494, apps/controller/src/drivers/compute/docker/index.ts:549-564 Live proof: unknown/not run | SupportedBoth roles reference the same persisted Agent-owned transport Secret; initial provisioning generates transport bytes only if that group is absent. This source evidence does not prove every runtime retry or external rotation scenario. Sourceapps/controller/src/drivers/compute/kubernetes/index.ts:4064-4074, apps/controller/src/drivers/compute/kubernetes/index.ts:909-923 Tests (not run)Live proof: unknown/not run | UnsupportedDedicated transport unsupported. Live proof: unknown/not run |
| ConnectivityHonor native trusted-proxy gateway authentication | optional capability | SupportedAt the reviewed baseline, explicit trusted-proxy mode omitted the gateway credential. The current Driver supports password or trusted-proxy authentication only; see the current Driver reference. Tests (not run)Live proof: unknown/not run | SupportedAt the reviewed baseline, private routing verified explicit trusted-proxy settings. The current Driver always renders trusted-proxy authentication from Installation settings; see the current Driver reference. Sourceapps/controller/src/drivers/compute/kubernetes/index.ts:3240-3255, apps/controller/src/drivers/compute/kubernetes/index.ts:4093-4102 Live proof: unknown/not run | SupportedAt the reviewed baseline, the trusted-proxy unit omitted its generated gateway credential file. The current Driver supports password or trusted-proxy authentication only; see the current Driver reference. Sourceapps/controller/src/drivers/compute/ssh/remote-helper.cjs:503-521, docs/reference/drivers/ssh-compute.md:197-201 Tests (not run)Live proof: unknown/not run |
| OperationsSchedule periodic active-runtime maintenance | optional capabilityRequirement source | UnsupportedNo maintenanceIntervalMs declaration; event-driven lifecycle. Sourceapps/controller/src/drivers/compute/docker/index.ts:231-238, docs/reference/drivers/compute.md:99-112 Live proof: unknown/not run | UnsupportedNo maintenanceIntervalMs declaration; Kubernetes controller handles workload reconciliation separately. Sourceapps/controller/src/drivers/compute/kubernetes/index.ts:629-638, docs/reference/drivers/compute.md:99-112 Live proof: unknown/not run | UnsupportedNo maintenanceIntervalMs declaration; systemd restart policy is distinct. Sourceapps/controller/src/drivers/compute/ssh/index.ts:253-261, docs/reference/drivers/ssh-compute.md:215-219 Live proof: unknown/not run |
| OperationsRuntime log collection path | implementation boundary | PartialOptional Docker Fluentd forwarding; Podman logging overlay remains unverified/unsupported on documented baseline. Sourceapps/controller/src/drivers/compute/docker/index.ts:626-628, apps/controller/src/drivers/compute/docker/index.ts:652-665, docs/reference/drivers/docker-compute.md:37-39 Live proof: unknown/not run | SupportedLabels workloads and supplies native admitted logging levels for collection. Sourceapps/controller/src/drivers/compute/kubernetes/index.ts:4012-4016, apps/controller/src/drivers/compute/kubernetes/index.ts:4184-4198 Live proof: unknown/not run | SupportedNative systemd stdout/stderr collected by journald. Sourceapps/controller/src/drivers/compute/ssh/remote-helper.cjs:503-532, docs/reference/drivers/ssh-compute.md:171-175 Live proof: unknown/not run |
| OperationsEnforce immutable runtime image digests | implementation boundaryRequirement source | UnsupportedAccepts engine-resolved tags as well as digests for development. Sourcedocs/reference/drivers/docker-compute.md:101-105, apps/controller/src/drivers/compute/docker/index.ts:240-247 Live proof: unknown/not run | SupportedProduction requires immutable SHA-256 image references. Tests (not run)Live proof: unknown/not run | UnsupportedHost binary paths are operator-managed; no container image pinning. Sourceapps/controller/src/drivers/compute/ssh/index.ts:42-47, docs/reference/drivers/ssh-compute.md:218-219 Live proof: unknown/not run |
Update this snapshot
Edit docs/assets/compute-driver-matrix.json after reviewing the intended source
revision. Keep implementation citations and test citations separate. Regenerate
this table with node scripts/generate-compute-matrix.mjs; the docs build rejects
a stale fallback. Follow local preview validation
and record executed proof separately from support judgments.
